PT-2024-31144 · Tenda · Tenda Fh1206
Published
2024-08-23
·
Updated
2024-12-13
·
CVE-2024-44390
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda FH1206 version V1.2.0.8(8155) EN
Description
The issue is a Buffer Overflow vulnerability via the function
formWrlsafeset(). This vulnerability can be exploited, but details about real-world incidents are not provided. The estimated number of potentially affected devices worldwide is not available.Recommendations
For Tenda FH1206 version V1.2.0.8(8155) EN, upgrade to version V1.2.0.9(8155) EN or later to resolve the issue. As a temporary workaround, consider disabling the
formWrlsafeset() function until a patch is available.Exploit
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Fh1206